TCPA Texting Rules for Practices: What Changed in 2026

A federal appeals court ruling in July 2026 changed how one specific TCPA lawsuit works for text messages — and […]

Practice staff member texting a patient on a smartphone in a dental or medical office, illustrating TCPA compliance for dental and medical practices
On this page

Share

A federal appeals court ruling in July 2026 changed how one specific TCPA lawsuit works for text messages — and headlines calling it a green light for unrestricted texting are wrong. TCPA compliance for dental and medical practices still requires patient consent before most texts go out; what changed is narrower than it sounds, and getting it wrong is still expensive.

Practices that text patients for appointment reminders, recall campaigns, review requests, or promotions are all operating under the Telephone Consumer Protection Act, a federal law that governs consent to contact — separate from HIPAA, which governs what health information can appear in that message. Confusing the two is the most common compliance mistake practices make, and it’s usually the reason a texting tool gets set up wrong from day one.

What Actually Happened in July 2026

On July 14, 2026, the Seventh Circuit Court of Appeals ruled in Steidinger v. Blackstone Medical Services that text messages don’t count as “telephone calls” under one specific part of the TCPA: Section 227(c), the Do-Not-Call registry provision that lets consumers sue directly over unwanted contact after opting out. The court reasoned that text messaging didn’t exist when the TCPA was written in 1991, so the word “call” in that section doesn’t stretch to cover texts.

That’s the whole ruling.

It does not touch Section 227(b), the part of the TCPA that actually governs consent for autodialed or prerecorded marketing texts — the rule most practices need to worry about day to day. It applies only within the Seventh Circuit (Illinois, Indiana, Wisconsin), and other circuits haven’t agreed; a circuit split is already forming, which means the Supreme Court may eventually settle it. And it does nothing to state-level “mini-TCPA” laws, several of which impose their own consent and do-not-text rules regardless of what a federal appeals court decides.

For a dental or medical practice reading a headline that says “court rules texting isn’t covered by TCPA,” the accurate translation is: one narrow type of private lawsuit got harder to bring in three states. The consent obligations that determine whether a practice can legally text a patient in the first place are unchanged.

TCPA vs. HIPAA: Two Different Rulebooks

TCPA compliance for dental and medical practices means satisfying two separate frameworks. TCPA and HIPAA answer two different questions, and a practice can pass one and still fail the other.

TCPA HIPAA
What it governs Consent to contact a phone number Protection of health information in the message
Applies to Every text sent to a U.S. mobile number Only messages sent by a covered entity or business associate
Consent required Yes — level depends on message type No prior consent required for treatment-related texts
What it restricts Who you can text, when, and how often What you can say in the text

A HIPAA authorization on file for a patient does not satisfy TCPA consent requirements, and TCPA consent doesn’t give a practice permission to put diagnosis or treatment detail into a plain SMS. Practices need to satisfy both, independently, for the same text message.

The Two Consent Tiers That Actually Matter

The single most useful thing to understand about TCPA compliance for dental and medical practices is that not all texts require the same level of consent.

Transactional and healthcare-treatment messages — appointment reminders, confirmations, pre-op instructions, post-discharge follow-up, lab result notifications — only need prior express consent, which can be given orally or in writing. If a patient hands over their cell number at intake and doesn’t object to being texted, that’s generally sufficient for this category.

Marketing and promotional messages — recall campaigns pitching a service, review requests tied to a discount, birthday offers, “$99 off Invisalign this month” texts — require the higher standard of prior express written consent. That means a signed or electronically confirmed opt-in that specifically covers marketing communication, not just general contact.

Most practices that run into trouble haven’t separated these two categories inside their own texting tool. They collect one blanket consent checkbox at intake, then use the same list for appointment reminders and promotional blasts. The reminder text is fine. The promotional text sent to that same list, without written marketing consent, is the one that creates exposure.

Patient completing an intake form with separate text message consent checkboxes for TCPA compliance
Separating transactional and marketing consent at intake is where most practices close their TCPA gap.

What This Looks Like in a Real Practice Workflow

TCPA compliance for dental and medical practices is less about legal theory and more about workflow. Practices that text patients at any real volume, whether directly or through a patient CRM, tend to get consent right when it’s built into three specific points in the workflow rather than handled as an afterthought:

  1. Intake forms separate the two consent types. One checkbox covers appointment and treatment-related texts. A second, clearly labeled checkbox covers marketing and promotional texts, with plain language about what that includes.
  2. Every automated message includes an opt-out instruction, and “STOP” requests are honored immediately and logged — not just acknowledged verbally at the front desk.
  3. Consent records are timestamped and stored inside whatever system sends the texts, so if a patient later disputes receiving a message, the practice can show when and how consent was captured.

Automated marketing texts are also restricted to the hours of 8:00 a.m. to 9:00 p.m. in the recipient’s local time zone. A practice with patients across time zones — common for telehealth or multi-location groups — needs to schedule sends against the patient’s zone, not the practice’s.

What It Costs to Get Wrong

Getting TCPA compliance for dental and medical practices wrong is not a paperwork issue; it carries real statutory penalties.
TCPA violations carry statutory penalties of $500 per message for a standard violation, rising to $1,500 per message if a court finds the violation willful or knowing. Those numbers apply per text, not per campaign, which is why a single promotional blast to an un-consented list can turn into a six-figure exposure fast, independent of any settlement or legal fees on top of it.

Common Mistakes Practices Make

These are the patterns that most often break TCPA compliance for dental and medical practices, even at well-run offices.

  • Assuming a HIPAA-compliant texting platform automatically means TCPA-compliant. The platform can encrypt and secure the message content and still be sending it to someone who never gave marketing consent.
  • Treating recall campaigns as “the same as appointment reminders” because they’re both about getting the patient back in the chair. A recall message that includes any promotional language — a discount, a “we miss you” offer — is marketing, not transactional.
  • Reading the July 2026 ruling as a compliance win and loosening consent practices. The ruling narrows one private right of action in three states; it doesn’t touch the underlying consent requirement that determines whether a text should have gone out in the first place.
  • Not documenting consent at all, relying on “the patient never complained” as a substitute for an actual, timestamped opt-in record.

The Bottom Line

TCPA compliance for dental and medical practices in 2026 comes down to two habits: separating transactional consent from marketing consent inside whatever tool sends the texts, and documenting that consent the same way every time. The July 2026 court ruling is a genuinely interesting development for litigation attorneys, but it doesn’t change what a practice should be doing at the intake desk this week.

FAQ

Do dental and medical practices need patient consent to send text messages?

Yes. TCPA compliance for dental and medical practices requires consent before most texts go out. Every text sent to a U.S. mobile number falls under the TCPA regardless of content. Appointment and treatment-related texts need prior express consent, which can be oral or written, while marketing and promotional texts need the higher standard of prior express written consent.

Is HIPAA authorization the same as TCPA consent for texting patients?

No. They’re separate requirements that operate independently. A HIPAA authorization covers what health information a practice can share; it says nothing about whether the practice has permission to contact that phone number. A practice needs both forms of consent satisfied, not one standing in for the other.

What are the penalties for violating TCPA with a text message?

Standard violations carry statutory damages of $500 per message, and courts can raise that to $1,500 per message for willful or knowing violations. Because penalties apply per message, a single non-compliant campaign sent to a large list can add up quickly.

Can appointment reminder texts violate TCPA, or are they treated differently from marketing texts?

They’re treated differently. Appointment reminders, confirmations, and other treatment-related messages only require prior express consent, oral or written. They become a problem when promotional content, like a discount or offer, gets mixed into what’s supposed to be a transactional message.

What time of day can practices legally text patients?

Automated texts are restricted to 8:00 a.m. to 9:00 p.m. in the recipient’s local time zone. Practices with patients in multiple time zones should schedule sends against each patient’s zone rather than the practice’s own.

Did the July 2026 Seventh Circuit ruling make it legal to text patients without consent?

No. The ruling in Steidinger v. Blackstone Medical Services only narrowed one specific type of lawsuit — private claims under the TCPA’s Do-Not-Call provision — and only within Illinois, Indiana, and Wisconsin. The core requirement to obtain consent before sending marketing texts is unchanged, and state-level texting laws still apply on top of it.

Keep reading
Five yellow stars on a pink and blue background, representing the FTC's review rating rules for medical and dental practices
HIPAA-Compliant Marketing

FTC Review Rules for Practices: What Changed in 2026

The FTC’s Consumer Review Rule changed how dental and medical practices can ask patients for reviews in 2026, with fines up to $53,088 per violation. What’s compliant, what isn’t, and where it overlaps with HIPAA.

Patient scheduling a dental appointment at the front desk, where Local Services Ads for dentists deliver every lead as a phone call
Digital Marketing

Local Services Ads for Dentists: What Changed in 2026

Local Services Ads for dentists changed in 2026. Google Screened is now Google Verified, the money-back guarantee is ending, and healthcare practices face two restrictions that decide whether the channel pays.

Scroll to Top